CVE-2026-103355: WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin <= 2.0.20 - SQL Injection vulnerability
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor allows Blind SQL Injection.This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 2.0.20.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
wordpress/unlimited-elements-for-elementorto a version that resolves this vulnerability.Fixed in 2.0.21
Event History
Frequently Asked Questions
Who can exploit this issue?
The CVSS vector indicates that exploitation can be performed remotely over the network, requires no privileges or user interaction, and has low attack complexity.
What is the potential impact?
Successful exploitation may allow blind SQL injection, with high potential impact to confidentiality and low potential impact to availability. The vector indicates no direct integrity impact.
Which versions are affected?
The issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates) through version 2.0.20. The available data does not identify a fixed version.